• 0 Posts
  • 6 Comments
Joined 3 years ago
cake
Cake day: June 13th, 2023

help-circle
  • Separate admin accounts is a good idea. It can be overdone. For example, you might decide you need one account for proxmox admin, one for network devices, a third for your IAM stack and a fourth for apps. I personally think that’s too much.

    Every human admin needs a separate admin account. If you’re using AI, each agent needs its own privileged access too.

    I recommend having as few privileged accounts as is reasonable. It might make sense to separate network admin from the rest, for example, or some other separation. But it might be fine in your case to have one master-admin account.

    Getting the mapping right is the hard part. Most IdP-aware apps have some way to map roles, groups, or whatever privilege management they use.






  • Authentication & single sign-on service

    Plugged into Reverse proxy, routing to each service by name

    With a wild card cert so there are no name leaks.

    Make your urls unexpected. If your domain is example.com, don’t put your jellyfin server at jellyfin.example.com. Instead, use watch.example.com or telly.example.com. Anything that’s memorable to you about what the service is without using a specific brand name.

    With a wildcard dns record to point all names to your IP, and a wildcard certificate that works for all names loaded on your load balancer, it becomes hard for a hacker to know what name to use to get the load balancer to send them to the service they want to hack.

    If you then use a sso tool like traefik’s ForwardAuth middleware, you won’t even get to the service until you’ve first authenticated.